---
title: "Where the Surplus Settles"
date: 2026-09-25
summary: "The Season 2 finale. Eight Fridays asked where advantage, money and power move once agents can act, and the closing question puts the season's own weeks on the ballot: objectives were Week 1, access Weeks 2 and 7, execution Weeks 3 and 4, verification Weeks 5 and 6. The room is ranking its own arguments without being told that is what it is doing. Two findings come out of the ledger rather than the news. The season's opening answer lost to itself — proprietary data took 78% of Week 1 when the question was what creates an edge, and 13% of Week 6 when it was what wins a bid — and two of the finale's four control points were already on the Week 1 ballot in different words, finishing at 4% and 7%, two of the three lowest scores of the season. The room prices what it imagines holding and discounts what it imagines going through. The week's term is Where the Surplus Settles, and the criterion is not refusal but binding refusal: surplus settles where the refused party has no substitute it can route to. That rules out the tidy version of this argument. Verification is not structurally excluded from capture, since credit rating agencies are pure examiners running operating margins around 64%; an examiner captures in proportion to how much its verdict moves the price, and in advertising it moves none — DoubleVerify measured 9.5 trillion transactions in FY2025 at seven cents per thousand, falling. Amazon told Perplexity no in writing, in code and in court and lost, not for want of authority but for want of a way to tell who was at the door, which makes refusal an identity problem before it is an access one. And binding refusal attracts the state: three federal courts found access rents and three declined to remove them, while the ad tech remedy left the asset in place and took away the refusal."
standfirst: "The Season 2 finale. The closing poll puts the season's own weeks on the ballot (objectives was Week 1, access Weeks 2 and 7, execution Weeks 3 and 4, verification Weeks 5 and 6), so the room ranks its own arguments without being told. Two findings come from the ledger: the season's opening answer lost to itself (proprietary data 78 percent of Week 1 asking what creates an edge, 13 percent of Week 6 asking what wins a bid), and two of the four control points were already on the Week 1 ballot in other words, finishing at 4 and 7 percent, two of the season's three lowest scores. The room prices what it imagines holding and discounts what it imagines going through. The term is Where the Surplus Settles and the criterion is binding refusal: surplus settles where the refused party has no substitute it can route to. Verification is not structurally excluded, since rating agencies are pure examiners running operating margins around 64 percent, but an examiner captures in proportion to how much its verdict moves the price, and in advertising it moves none: DoubleVerify measured 9.5 trillion transactions in FY2025 at seven cents per thousand, falling while volume rose, and the MRC suspended Nielsen for nineteen months while Nielsen grew and sold for 16 billion dollars. Amazon told Perplexity no in writing, in code and in court and lost, for want of a user-agent string rather than authority, which makes refusal an identity problem first. And binding refusal attracts the state: three courts found access rents and three declined to remove them, while the ad tech remedy left the asset in place and took away the refusal. Checkable close: a take rate that does not fall as a market matures is the signature of a control point that can refuse. The closing poll went to executing trades, 53% of 13 ballots, with verifying outcomes 23, setting objectives 15 and controlling access 7; the author voted verifying outcomes and calls the result the one he is least equipped to argue with."
canonical: https://nofluffadvisory.com/writing/where-the-surplus-settles/
---

## The question the season already answered

Season 2 asked where advantage, money and power move once agents can act. Eight Fridays, eight questions, one reusable term a week. The last question is *where will agentic market power concentrate?* — and the four options on the ballot are not four ideas I picked this week. They are the season's own weeks, wearing different words.

Setting objectives was Week 1. Controlling access was Weeks 2 and 7. Executing trades was Weeks 3 and 4. Verifying outcomes was Weeks 5 and 6. So the room is not being asked a new question. It is being asked to rank its own arguments, without being told that is what it is doing.

Season 1's finale discovered its recursion after the fact and had to reverse-engineer the pattern. This one was built that way from the first Friday, which means the ledger below is evidence rather than decoration.

## Eight Fridays, one ledger

| Wk | Term | The question | The vote | My vote |
| :--- | :--- | :--- | :--- | :--- |
| 1 | The Mandate Premium | What creates the edge? | Proprietary data 78% of 42 · Faster execution 9 · Privileged access 7 · Clearer mandate 4 | Proprietary data |
| 2 | The Eligibility Layer | What is the new shelf space? | Retrieval results 31% and Paid recommendations 31% of 16 · Training data 18 · Default integrations 18 | Paid recommendations |
| 3 | Outcome Underwriting | What will agents ultimately buy? | Outcomes 57% of 73 · Impressions 27 · Audiences 8 · Attention 6 | Outcomes |
| 4 | Negotiating the Nouns | What gets negotiated hardest? | Success criteria 34% of 55 · Price 32 · Audience definitions 16 · Liability 16 | Success criteria |
| 5 | The Risk Residue | Which intermediary function survives? | Assuming risk 42% of 19 · Finding counterparties 21 · Verifying results 21 · Negotiating price 16 | Assuming risk |
| 6 | The Evidence Premium | What wins the bid? | Verifiable outcomes 54% of 37 · Lowest price 21 · Proprietary data 13 · Exclusive supply 10 | Verifiable outcomes |
| 7 | Interface Capture | Who owns the customer relationship? | The consumer 31% of 19 · The brand 26 · The agent platform 26 · The data holder 15 | The brand |
| 8 | Where the Surplus Settles | Where does power concentrate? | Executing trades 53% of 13 · Verifying outcomes 23 · Setting objectives 15 · Controlling access 7 | Verifying outcomes |

Two hundred and seventy-four ballots across eight weeks, against Season 1's 512. Turnout ran from 13 to 73. That is a straw poll of people who follow this subject for a living and it forecasts nothing; on a sixteen-ballot week the gap between first and second is noise. The order carries the information, the margins mostly do not, and the comparisons between weeks carry more than either.

> [figure: Season 2, After Permission: eight Fridays, one ledger. One row per week, each showing the week's term and its whole four-option ballot as a single stacked bar, largest share first, scaled so every bar fills the same track. The winning segment is drawn in a warm colour and named above the bar with its share; the other three are in graded grey tones with their shares as small numerals; a tick marks the segment I voted for; the ballot count sits at the right edge. Week 1, The Mandate Premium, 42 ballots: Proprietary data 78 percent, Faster execution 9 percent, Privileged access 7 percent, Clearer mandate 4 percent; my vote, Proprietary data. Week 2, The Eligibility Layer, 16 ballots: Retrieval results 31 percent, Paid recommendations 31 percent, Training data 18 percent, Default integrations 18 percent, a tie at the top with both segments in the warm colour; my vote, Paid recommendations. Week 3, Outcome Underwriting, 73 ballots: Outcomes 57 percent, Impressions 27 percent, Audiences 8 percent, Attention 6 percent; my vote, Outcomes. Week 4, Negotiating the Nouns, 55 ballots: Success criteria 34 percent, Price 32 percent, Audience definitions 16 percent, Liability 16 percent; my vote, Success criteria. Week 5, The Risk Residue, 19 ballots: Assuming risk 42 percent, Finding counterparties 21 percent, Verifying results 21 percent, Negotiating price 16 percent; my vote, Assuming risk. Week 6, The Evidence Premium, 37 ballots: Verifiable outcomes 54 percent, Lowest price 21 percent, Proprietary data 13 percent, Exclusive supply 10 percent; my vote, Verifiable outcomes. Week 7, Interface Capture, 19 ballots: The consumer 31 percent, The brand 26 percent, The agent platform 26 percent, The data holder 15 percent; my vote, The brand, the first week my vote was not the top answer. In Week 1 the two smallest answers are called out by name: Privileged access 7 and Clearer mandate 4. Week 8, Where the Surplus Settles, 13 ballots: Executing trades 53 percent, Verifying outcomes 23 percent, Setting objectives 15 percent, Controlling access 7 percent; my vote, Verifying outcomes, the second week my vote was not the top answer. Footer: 274 ballots across eight weeks; turnout ran from 13 to 73.]

## The noun that lost to itself

Here is the season in one comparison, and it is not flattering to me.

Week 1 asked what creates the edge when every advertiser has a capable buying agent. Proprietary data took 78% — the largest number of the season, and close to unanimous for a four-way question. Week 6 asked what wins the bid when every seller can claim performance. Proprietary data took 13%, third of four.

Same noun. Same feed. Five weeks apart. The room valued the asset at 78% when the question put it in their hands, and at 13% when the question put it on the other side of a bid.

I voted for it in Week 1. That is the part worth stating plainly rather than burying in a parenthesis: the season's opening answer was mine, and the season demoted it. Week 6's essay already named the mechanism for the seven-day version of this: a room answering two questions that happen to share a noun. This is the same effect stretched across a season. What changed is not the room's information. What changed is whose side of the transaction the question stood on.

## What the room was already asked

Now the uncomfortable part, and it is the reason this finale can be checked rather than merely asserted.

Two of this week's four control points were already on the Week 1 ballot, in different words. *Clearer mandate* is setting objectives. *Privileged access* is controlling access. They finished at **4%** and **7%** — two of the three lowest scores any option received in the entire season.

So had the room crowned controlling access, it would have reversed itself on the same idea by roughly an order of magnitude, in eight weeks, with no new external event forcing the change. Had it crowned setting objectives, the reversal would have been larger still. It did neither.

I do not think that is fickleness, and the bias has a shape worth naming: **the room prices what it imagines holding and discounts what it imagines going through.** Week 1 asked what gives *you* an edge, and the room picked an asset it could own. This week asks where power *concentrates*, which is a question about somebody else's position. The same control point is cheap when you picture yourself needing it and expensive when you picture yourself standing at it.

That is not a flaw in the room. It is the single most useful thing eight weeks of polling produced, because it is also how budgets get written.

## Where the surplus settles

**Where the Surplus Settles:** surplus settles where refusal is *binding* — where the party being refused has no substitute it can route to.

I want to be precise about what that replaces, because the version I started with was wrong and a reader would have taken it apart. The claim is not that one control point can refuse and the others cannot. Refusal is available almost everywhere and worth almost nothing in most places. An internet service provider can refuse absolutely, and captures approximately none of the economics of advertising, because the refusal gets routed around one layer up. The test is not whether you can say no. It is whether your no leaves the other side without a route.

That reframing costs me the tidier sentence and keeps all four of the ballot's control points genuinely in contention, which is the honest position. Access usually qualifies because substitution is expensive. Execution can qualify: first look and last look were binding refusals, which is exactly why they produced surplus and exactly why a court has now ordered them stopped. And verification qualifies whenever somebody else's rulebook makes the stamp a condition of entry.

## The examiner's test

My draft said verification cannot capture surplus. That is false, and the counter-example is enormous.

Credit rating agencies are pure examiners. They own no inventory, execute no trades and hold no customer relationship. Moody's Investors Service ran an adjusted operating margin around 64% in Q2 2025; S&P Global Ratings reported an operating margin of 64% for the twelve months to 31 December 2025. Meanwhile the two independent advertising verifiers, DoubleVerify and Integral Ad Science, booked roughly $1.35bn between them. Against global digital ad spend that is well under one percent of the market they measure, on any denominator you choose.

Same function, opposite economics. The variable is not what layer you sit in. It is this:

> An examiner captures surplus in proportion to how much its verdict moves the price of the thing being sold.

A Moody's verdict moves a coupon by basis points on billions of dollars of issuance, so the issuer pays and the examiner keeps rating-agency margins without any power to exclude anyone. A DoubleVerify verdict moves nothing. The impression clears at the same CPM whether it was verified or not, because verification in advertising is a procurement record rather than a price input.

> [figure: The examiner's test, drawn as two lanes with the same function and opposite economics. Lane one, credit rating agencies, Moody's Investors Service and S&P Global Ratings: a Moody's verdict moves a coupon by basis points on billions of dollars of issuance, so the issuer pays and the examiner keeps rating-agency margins without any power to exclude anyone; the chain ends in an operating margin around 64 percent. A note records that they are pure examiners that own no inventory, execute no trades and hold no customer relationship, and that the figures are Moody's adjusted margin for Q2 2025 and S&P Global Ratings for the twelve months to 31 December 2025. Between the lanes the rule is set as a line: an examiner captures surplus in proportion to how much its verdict moves the price of the thing being sold. Lane two, ad verifiers, DoubleVerify and Integral Ad Science: a DoubleVerify verdict moves nothing. The impression clears at the same CPM, because verification in advertising is a procurement record rather than a price input, and the chain ends in unit price down 3 percent while volume rose 15 percent. A note records roughly 1.35 billion dollars booked between the two verifiers, well under one percent of the market they measure, and DoubleVerify's FY2025 figures: 9.5 trillion media transactions measured, up 15 percent, at a measured transaction fee of 0.07 dollars per thousand, down 3 percent. A bottom strip shows the natural experiment as a timeline bar that runs the length of the suspension, with three stops: at the start, in September 2021, the Media Rating Council suspends Nielsen's television accreditation; 209 days into the suspension the company is sold for 16 billion dollars without a discount for it; at the end of the bar, nineteen months later, accreditation returns, only for national television. The closing line reads: the examiner refused, and the market did not move.]

DoubleVerify's own filings say it more clearly than I could. In FY2025 it measured 9.5 trillion media transactions, up 15%, at a measured transaction fee of $0.07 per thousand, down 3%. Unit price falling while volume rises is the signature of a commodity, not a toll. The same 10-K concedes that platform partners "have significant control over how DoubleVerify's solutions are provided on their platforms" and "in many instances, are able to provide these competitive solutions at significantly lower rates or for free." The first clause matters more than the second: control over whether the examiner may measure at all is an access statement, not a pricing one.

And the natural experiment has already run. The Media Rating Council accredits the measurement that US advertising transacts against, on an annual budget of about $3.2m. In September 2021 it suspended Nielsen's television accreditation. Nielsen said the suspension would not affect the usability of its data, and it was right: revenue grew, the company was sold for $16bn 209 days into the suspension without a discount for it, and when accreditation returned nineteen months later it returned only for national television. The examiner refused, and the market did not move.

Then in August 2026 the loop closed in the most literal way available. Nielsen agreed to buy DoubleVerify for about $2.15bn — the measurement firm that lost its accreditation and kept the currency buying the verification firm that kept its accreditation and lost its multiple. The financing tells you what was bought: roughly $1.8bn of committed debt against $245.6m of adjusted EBITDA. Nobody levers a chokepoint seven times. You lever a cash flow. The deal is pending and expected to close in 2027, and Nielsen has promised to maintain the independence of both operating structures, which is the sentence I would keep a copy of.

## Refusal needs an identity layer

Here is the finding that reorganised this essay, and it came from the case I expected to be a wound.

Amazon told Perplexity no. It said so to Perplexity's chief executive before Comet shipped, said so again afterward, and then said so in federal court. On 4 August 2026 the Ninth Circuit vacated its injunction. But read what the dispute actually turned on: Perplexity's decision not to send a user-agent string, the mechanism that would have identified the traffic as an agent and let Amazon block it. The panel's own footnote leaves Amazon free to regulate access to its store through private terms.

So Amazon's refusal did not fail for want of authority. It failed for want of a way to tell who was at the door.

Set that beside the cleanest counter-case available. In December 2020 Visa and Mastercard refused to process payments for Pornhub, and the site removed the majority of its content within four days. The payment network's no was absolute because the network knew precisely whom it was refusing. Same variable, opposite outcome.

The web's traditional refusal mechanism was never a refusal at all. RFC 9309, the standard that specifies robots.txt, disposes of it in one sentence: "These rules are not a form of access authorization."

Which means the gate needs the clipboard. Refusal is a verification function wearing an access hat, and the season's third and fourth options are less separate than the ballot makes them look. Whoever can identify the counterparty can refuse it, and whoever can refuse it can price it.

The agentic era did not abolish the right to say no. It made saying no conditional on an identity layer that does not exist yet.

## Binding refusal attracts the state

The other half of the answer is that this position is not safe, and the pattern is consistent enough to state as a rule.

In 2023 the Ninth Circuit recorded that Apple's App Store margins "have exceeded 75% for years" and that the commission had been set almost by accident, without regard to cost — and affirmed the denial of antitrust liability anyway. A court found the price untethered from cost and held it lawful. In December 2025 the same court wrote that "Apple has demonstrated that charging commissions on linked-out purchases gives it the power to prohibit them," then reversed the district court's total ban on those commissions and sent it back. The fight is now over the rate, not the right.

In September 2025, having found Google liable in the search case, Judge Mehta declined to ban the distribution payments: "Though the bases for a payment ban are sound, the court declines to impose such a remedy at this time." His reasoning is the strongest evidence in this essay. Ending the payments would hand Google a windfall worth tens of billions and leave distributors a Hobson's choice. The rent is so structural that removing it would enrich the party paying it.

And in the ad tech case, Judge Brinkema's April 2025 liability finding treated Google's durable ability to hold a 20% take rate on AdX, and its unwillingness to lower it as the market matured and rivals cut theirs, as direct proof of monopoly power. In September 2026, as reported, she declined every structural remedy including divestiture and reworked the auction's mechanics instead.

Note what that is. The remedy did not move the asset. It removed the refusal.

That is the durability clause, and it belongs in the answer rather than in a footnote. A control point that can refuse captures surplus right up until refusing becomes illegal, and binding refusal is exactly the thing that attracts the state. Nothing here is settled: the ad tech opinion is under seal as I write, the proposed final judgment is not due until after this essay publishes, and an appeal is close to certain.

## The test you can run

The useful form of all this is not a declaration about who wins. It is a check anyone can run on whichever agentic control point they are betting on, and Brinkema handed it over:

**A take rate that does not fall as the market matures is the signature of a control point that can refuse.**

Run it on the numbers in this essay. AdX held 20% while rivals cut theirs, and a court called that durability proof of power. DoubleVerify's fee per thousand fell 3% in a year when the volume it measured rose 15%. One of those is a gate. The other is a service.

The example I least expected is OpenAI, which holds the purest interface position in the industry. It built a checkout inside ChatGPT and then narrowed it: the dedicated help page has been withdrawn, OpenAI now says the option appears only "for some eligible products and merchants," and Shopify sends ChatGPT shoppers to the merchant's own checkout. Over the same months OpenAI built an advertising business on the interface itself, which it says passed a billion dollars in annualized revenue run rate in under two hundred days. Read through the binding-refusal test, that is an access point declining to gate a transaction the buyer could finish one click away, and monetising the position instead.

## Running the four

*Setting objectives.* The room priced this at 4% in Week 1 and I see no reason to overturn it. An advertiser can restate a mandate at no cost and with nobody's permission. Something everyone can do and nobody can be denied is a precondition, not a control point.

*Executing trades.* The season moved the interesting question off execution and onto what is traded (outcomes, 57%) and who defines it (success criteria, 34%). But this is the option my argument is weakest against, and the ad tech case is the reason: first look and last look were execution mechanics that functioned as binding refusals, and they produced enough surplus to become the centre of a monopolisation finding. Execution captures when it can exclude. It usually cannot.

*Verifying outcomes.* The room's strongest sustained conviction, and I voted with it twice. It is not structurally excluded from capture, as my first draft wrongly claimed — it is excluded whenever its verdict does not move the price. In advertising today it does not. Wire an examiner's stamp into somebody's condition of entry and the economics invert, which is what IAB Tech Lab announced for AAMP 2.3 in July, an approval gate on the buyer agent's price-moving path, and what AdCP is circling in an open proposal to reserve an authoritative party for billing. Both are worth watching and neither has yet moved a price.

*Controlling access.* The option the room rated at 7% in Week 1. It wins on the current arrangement rather than by nature, it wins only where substitution is expensive, it depends on an identity layer that agentic traffic has not yet built, and it is the position most likely to be regulated out from under whoever holds it.

> [figure: The essay's binding-refusal test applied to the four control points on the season's closing ballot, drawn as a four-row matrix. The headline asks: four control points, one test, does the refusal bind? This is the essay's argument, not a poll result: no vote on the closing question is shown and the rows follow the essay's order. The columns are: can it refuse, does the refusal bind, the evidence, and a verdict. Binding means the party being refused has no substitute it can route to. Setting objectives, Week 1: it cannot refuse and nothing binds, because an advertiser can restate a mandate at no cost, and the room priced it at 4 percent in Week 1. Verdict stamp: a precondition, not a control point. Executing trades, Weeks 3 and 4: it usually cannot refuse, and the refusal binds when it can. First look and last look did exclude, and a court ordered them stopped. Verdict stamp: captures when it can exclude. Verifying outcomes, Weeks 5 and 6: it can refuse, but the refusal does not bind, because in advertising today it moves no price. The AAMP 2.3 approval gate and an open AdCP proposal are worth watching, and neither has yet moved a price. Verdict stamp: only if its verdict moves the price. Controlling access, Weeks 2 and 7: it can refuse only with an identity layer that is not yet built, shown as a half mark labelled needs identity, and the refusal usually binds. Rated 7 percent in Week 1, it also needs substitution to be expensive. Verdict stamp: wins on the current arrangement. A note records that access wins on the current arrangement rather than by nature, and that it is also the position most likely to be regulated out from under whoever holds it. Beneath the matrix is the test you can run: a take rate that does not fall as the market matures is the signature of a control point that can refuse. Three bars are drawn against a starting level: the AdX bar ends exactly on it, the DoubleVerify fee bar stops 3 percent short of it, and the volume bar runs 15 percent past it. The AdX take rate held at 20 percent while rivals cut theirs, and is labelled a gate. DoubleVerify's fee per thousand fell 3 percent in a year while the volume it measured rose 15 percent, and is labelled a service. One of those is a gate. The other is a service.]

## The room's verdict

**Executing trades, 53% of 13.** Verifying outcomes 23%, setting objectives 15%, controlling access 7%. Thirteen ballots is the smallest room of the run, and 53% of it is seven people.

It is the result I am least equipped to argue with, and the case law is on the room's side rather than mine. First look and last look were execution mechanics that worked as binding refusals and generated enough surplus to anchor a monopolisation finding. If the room believes the definitional work gets absorbed into the execution layer rather than settled above it, the ad tech case is its evidence and this essay is its counterargument.

One more thing the ledger says about this ballot. The two options that finished last in Week 1, clearer mandate at 4% and privileged access at 7%, finished last again here as setting objectives and controlling access. Asked twice in different words, seven weeks apart, the room discounted the same two control points both times.

## My vote

I voted verifying outcomes. The room put it second at 23%, behind executing trades at 53%.

The season convicted three of my own ballots and I would rather say so than let a reader find it. I voted proprietary data in Week 1 and watched the same asset finish at 13% by Week 6. I voted verifiable outcomes in Week 6, and then wrote the sentence in that essay which undercuts verification as a place surplus settles. I voted verifying outcomes again here, in an essay that argues verification captures least on the current arrangement; the ballot and the essay disagree, and I am leaving both on the record, with the condition under which the ballot turns out right at the end of this section. My first draft of this finale claimed verification structurally cannot capture, which the rating agencies falsify at a scale that is not close. One prediction held: in Week 7 I wrote that I expected controlling access to be undervalued, for the same reason the data holder was, and it was: 7%, last, the score it took in Week 1 as privileged access.

The interest to declare matters more here than in any other week: I co-lead AdCP's Signals and Measurement working group. The layer I work on is the one this essay argues captures least, on the current arrangement. I am not going to pretend the finding flatters the work, and I would rather publish the version that survived being attacked than the version that read well.

What would change my mind is now specific rather than rhetorical. If an examiner's verdict starts moving a price in advertising, so that a seller can charge more for the same inventory because of who attested to it and can show the spread, then verification has become a price input rather than a procurement record, and the surplus moves with it.

## Coda — eight Fridays, one counter

Season 1 ended on an empty layer: nobody mints, prices or revokes the credential an agent acts under, and empty layers in load-bearing positions do not stay empty. Season 2 spent eight weeks on the question that follows and arrives back at the same verb from the other side. *Revokes.*

Season 1 found that nobody issues. Season 2 finds what issuing would be worth: everything, if the revocation binds, and two tenths of one percent if it does not. The Media Rating Council has the power to withdraw and a $3.2m budget. Moody's has the same power wired into a capital rule and sixty-four point margins. The difference between them is not competence, effort or rigour. It is whether anyone else's rules make the certificate a condition of entry.

Which is a strange place for a season about agents to land, and I think it is the right one. The question was never who is smartest, fastest or best instrumented. It is who can shut the door, on whom, and for how long before someone makes them open it.
